Total CVEs

140,319

Critical Severity

3,712

High Severity

13,362

Last 7 Days

1,805
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 8,941 - 8,960 of 13,059 CVEs
CVE-2025-13777 HIGH - 8.3

Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

Vendor: ABB
Product: AWIN GW100 rev.2, AWIN GW120
Published: Mar 13, 2026
Source: NVD
CVE-2026-31882 HIGH - 7.5

Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic authentication (DAGU_AUTH_MODE=basic), all Server-Sent Events (SSE) endpoints are accessible without any credentials. This allows unauthenticated attackers to access real-time DAG ex...

Vendor: npm
Product: dagu
Published: Mar 13, 2026
Source: GitHub
CVE-2026-2229 HIGH - 7.5

ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-deflate compression. ...

Vendor: npm
Product: undici
Published: Mar 12, 2026
Source: NVD
CVE-2026-1528 HIGH - 7.5

ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6....

Vendor: npm
Product: undici
Published: Mar 12, 2026
Source: NVD
CVE-2026-1526 HIGH - 7.5

The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on...

Vendor: npm
Product: undici
Published: Mar 12, 2026
Source: NVD
CVE-2026-32319 HIGH - 7.5

Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integrity protected NGAP/NAS message with a length under 7 bytes. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all co...

Vendor: go
Product: github.com/ellanetworks/core
Published: Mar 12, 2026
Source: GitHub
CVE-2026-32302 HIGH - 8.1

OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin validation when gateway.auth.mode was set to trusted-proxy and the request arrived with proxy headers. A page served from an untrusted origin could connect through a trusted reverse ...

Vendor: npm
Product: openclaw
Published: Mar 12, 2026
Source: GitHub
CVE-2026-32260 HIGH - 8.1

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_process polyfill (shell: true mode) that bypasses the fix for CVE-2026-27190. The two-stage argument sanitization in transformDenoShellCommand (ext/node...

Vendor: denoland
Product: deno
Published: Mar 12, 2026
Source: NVD
CVE-2026-32247 HIGH - 8.1

Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerability in shared search-filter construction for non-Kuzu backends. Attacker-controlled label values supplied through SearchFilters.node_labels ...

Vendor: getzep
Product: graphiti
Published: Mar 12, 2026
Source: NVD
CVE-2026-32246 HIGH - 8.5

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain authorization codes. An attacker who knows a user's password but not their TOTP secret can obtai...

Vendor: steveiliop56
Product: tinyauth
Published: Mar 12, 2026
Source: NVD

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.

Vendor: qhkm
Product: zeptoclaw
Published: Mar 12, 2026
Source: NVD
CVE-2026-32231 HIGH - 8.2

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request body and applies authorization checks to those untrusted values. Because authentication is optional and defaults to disabled (auth_token: None),...

Vendor: qhkm
Product: zeptoclaw
Published: Mar 12, 2026
Source: NVD
CVE-2026-32138 HIGH - 8.2

NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability was identified where Firebase and Web3Forms API keys were exposed. An attacker could use these keys to interact with backend services wi...

Vendor: Stalin-143
Product: website
Published: Mar 12, 2026
Source: NVD
CVE-2025-70873 HIGH - 7.5

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

Published: Mar 12, 2026
Source: NVD
CVE-2026-32274 HIGH - 7.5

Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker who controls the value...

Vendor: pip
Product: black
Published: Mar 12, 2026
Source: GitHub
CVE-2026-32141 HIGH - 7.5

flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indices, the recursion depth is unbounded, causing a stack ove...

Vendor: WebReflection
Product: flatted
Published: Mar 12, 2026
Source: NVD
CVE-2026-32140 HIGH - 8.8

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous JDBC properties, leading to remote code execution...

Vendor: dataease
Product: dataease
Published: Mar 12, 2026
Source: NVD
CVE-2026-32137 HIGH - 8.8

Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user-controllable string, attackers can inject malicio...

Vendor: dataease
Product: dataease
Published: Mar 12, 2026
Source: NVD

soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (PoseidonSponge) accepts variable-length inputs without injective padding. When a caller provides fewer inputs than the sponge rate (inputs.len() < T - 1), unused rate positions ...

Vendor: stellar
Product: rs-soroban-poseidon
Published: Mar 12, 2026
Source: NVD
CVE-2026-32116 HIGH - 8.1

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wormhole receive) from a malicious party could result in overwriting critical local files, including ~/.ssh/authorized_keys and .bashrc. This co...

Vendor: magic-wormhole
Product: magic-wormhole
Published: Mar 12, 2026
Source: NVD